Skip to content

Security: agentstation/starport

Security

SECURITY.md

Security Policy

Supported Versions

The latest Starport v1 release receives security fixes. Development snapshots and older releases do not receive separate security support.

Report a Vulnerability

Email security reports to security@agentstation.ai. Do not open a public issue for a suspected vulnerability.

Include the affected version or commit, the deployment mode, reproduction steps, the security effect, and any proposed remediation. Remove provider keys, gateway keys, master keys, account data, and other secrets from every report and attachment.

We will confirm receipt, assess the report, and coordinate remediation and disclosure with the reporter. Do not disclose an unresolved report publicly before that coordination is complete.

If a report, log, trace, or reproduction included a secret, revoke and replace it immediately. Starport cannot recover or validate an exposed secret.

Deployment Security Posture

The security review answers live in docs/SECURITY-POSTURE.md: the credential model, encryption at rest, authentication, the audit surface, and what leaves the process. This file owns vulnerability disclosure only.

There aren't any published security advisories